Skip to content

Registry deploy model: GHCR images + pull-based server deploy - #122

Merged
obchain merged 4 commits into
mainfrom
feat/registry-deploy
Jun 15, 2026
Merged

obchain merged 4 commits into
mainfrom
feat/registry-deploy

Conversation

@obchain

@obchain obchain commented Jun 15, 2026

Copy link
Copy Markdown
Owner

Switches the deploy model from build-on-server to pull pre-built images (no source on the host), per the requirement to deploy via Docker images rather than a git checkout.

Changes

docker-compose.prod.yml — the four app services now carry image: ghcr.io/${owner}/volx-<svc>:${VOLX_TAG:-latest} alongside build: (build for local, image for the server pull). Keeper secrets move to ${SEPOLIA_RPC_URL}/${PRIVATE_KEY} (compose-dir .env or exported shell env) and cloudflared to ${TUNNEL_TOKEN}, so no .secrets/*.env file mounts / source tree are required on the host.

scripts/deploy.sh — rewritten: docker compose pull && up -d --remove-orphans (recreates only services whose image digest changed) + dangling-image prune. No git, no on-host build. Runs from a standalone dir (compose + clickhouse-init.sql + deploy.sh + .env). --tunnel enables the cloudflared profile.

.github/workflows/deploy.yml — now a two-stage pipeline:

  1. build (matrix: api/engine/ingestion/keeper) → build + push to GHCR with GITHUB_TOKEN, tags latest + commit SHA, GHA layer cache.
  2. deploy → ship compose + deploy.sh over Cloudflare SSH, run the pull-based deploy.

Server holds only

~/volx-deploy/: docker-compose.prod.yml, clickhouse-init.sql, deploy.sh, and .env (keeper secrets, placed once by hand). No repo clone.

One-time setup

  • GitHub secret SERVER_SSH_KEY (+ optional SERVER_KNOWN_HOSTS).
  • Make the GHCR packages public (so the server pulls without registry login), or add a server-side docker login ghcr.io.
  • Create ~/volx-deploy/.env on the server with SEPOLIA_RPC_URL + PRIVATE_KEY.

Compose validated (config -q); deploy.sh bash -n clean; deploy.yml YAML valid (jobs build, deploy; matrix covers all 4 images).

obchain added 4 commits June 15, 2026 14:00
Add image: refs (ghcr.io/${owner}/volx-<svc>:${tag}) to the four app services
alongside build:, so the server pulls pre-built images instead of building from
source. Switch keeper signer secrets to ${SEPOLIA_RPC_URL}/${PRIVATE_KEY} (from
a compose-dir .env or exported shell env) and cloudflared to ${TUNNEL_TOKEN},
dropping the .secrets/*.env file mounts so no source tree is needed on the host.
Rewrite deploy.sh to pull pre-built images and recreate only the services whose
digest changed (docker compose pull && up -d), instead of git-pulling and
building on the host. Runs from a standalone dir holding just the compose file,
clickhouse-init.sql, deploy.sh, and .env. Optional --tunnel enables cloudflared.
Replace the build-on-server deploy with a registry pipeline: a matrix job builds
the four backend images and pushes them to GHCR (tags latest + sha) using
GITHUB_TOKEN, then the deploy job ships the compose + deploy.sh over Cloudflare
SSH and runs the pull-based deploy. No registry or app secrets pass through the
deploy step beyond SERVER_SSH_KEY.
…perms

Source the server .env in deploy.sh and run docker login ghcr.io when GHCR_TOKEN
is set, so private packages pull (public still pull anonymously). Scope
packages:write to the build job only; deploy gets contents:read.
@obchain
obchain merged commit e5635c6 into main Jun 15, 2026
@obchain
obchain deleted the feat/registry-deploy branch June 15, 2026 08:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant